Improper access control in Discourse - CVE-2023-49099
Published: January 9, 2024 / Updated: July 1, 2026
Discourse
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in secure upload URLs associated with posts when handling direct requests to protected uploads. A remote attacker can access a secure upload URL to disclose sensitive information.
User interaction is required to obtain or follow the upload URL.